---
id: CVE-2019-10219
title: A vulnerability was found in Hibernate-Validator
summary: >-
  A vulnerability was found in Hibernate-Validator. The SafeHtml validator
  annotation fails to properly sanitize payloads consisting of potentially
  malicious code in HTML comments and instructions. This vulnerability can
  result in an XSS a…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
  - CWE-79
vendor: redhat
product: hibernate_validator
affected:
  - hibernate_validator < 6.0.18
  - hibernate_validator = 6.1.0
  - fuse = 1.0
  - jboss_data_grid
  - jboss_enterprise_application_platform
  - openshift_application_runtimes
  - single_sign-on
  - jboss_enterprise_application_platform = 7.2
  - jboss_enterprise_application_platform = 7.3
  - active_iq_unified_manager
  - management_services_for_element_software_and_netapp_hci
  - snapcenter_plug-in
  - element
  - access_manager = 11.1.2.3.0
  - access_manager = 12.2.1.3.0
  - access_manager = 12.2.1.4.0
  - agile_engineering_data_management = 6.2.1.0
  - agile_plm = 9.3.3
  - agile_plm = 9.3.6
  - agile_product_lifecycle_analytics = 3.6.1
  - agile_product_lifecycle_management_integration_pack = 3.6
  - airlines_data_model = 12.1.1.0.0
  - airlines_data_model = 12.2.0.1.0
  - application_express = 21.1.4
  - application_performance_management = 13.4.1.0
  - application_performance_management = 13.5.1.0
  - application_testing_suite = 13.3.0.1
  - argus_analytics = 8.2.1
  - argus_analytics = 8.2.2
  - argus_analytics = 8.2.3
  - argus_analytics = 8.21
  - argus_insight = 8.2.1
  - argus_insight = 8.2.2
  - argus_insight = 8.2.3
  - argus_safety = 8.2.1
  - argus_safety = 8.2.2
  - argus_safety = 8.2.3
  - banking_apis = 18.1
  - banking_apis = 18.2
  - banking_apis = 18.3
  - banking_apis = 19.1
  - banking_apis = 19.2
  - banking_apis = 20.1
  - banking_apis = 21.1
  - banking_deposits_and_lines_of_credit_servicing = 2.12.0
  - banking_digital_experience = 17.2
  - banking_digital_experience = 18.1
  - banking_digital_experience = 18.3
  - banking_digital_experience = 19.1
  - banking_digital_experience = 19.2
  - banking_digital_experience = 20.1
  - banking_digital_experience = 21.1
  - banking_enterprise_default_management = 2.6.2
  - banking_enterprise_default_management = 2.7.0
  - banking_enterprise_default_management = 2.7.1
  - banking_enterprise_default_management = 2.10.0
  - banking_enterprise_default_management = 2.12.0
  - 'banking_enterprise_default_managment >= 2.3.0, <= 2.4.0'
  - banking_loans_servicing = 2.12.0
  - banking_party_management = 2.7.0
  - 'banking_platform >= 2.3.0, <= 2.4.1'
  - banking_platform = 2.6.2
  - banking_platform = 2.7.0
  - banking_platform = 2.7.1
  - bi_publisher = 5.5.0.0.0
  - bi_publisher = 11.1.1.9.0
  - bi_publisher = 12.2.1.3.0
  - bi_publisher = 12.2.1.4.0
  - big_data_spatial_and_graph = 23.1
  - business_activity_monitoring = 12.2.1.4.0
  - business_intelligence = 5.5.0.0.0
  - business_intelligence = 5.9.0.0.0
  - business_intelligence = 12.2.1.3.0
  - business_intelligence = 12.2.1.4.0
  - business_process_management_suite = 12.2.1.3.0
  - business_process_management_suite = 12.2.1.4.0
  - clinical = 5.2.1
  - clinical = 5.2.2
  - commerce_guided_search = 11.3.2
  - 'commerce_platform >= 11.3.0, <= 11.3.2'
  - communications_application_session_controller = 3.9.0
  - communications_billing_and_revenue_management = 12.0.0.3
  - communications_billing_and_revenue_management = 12.0.0.4
  - communications_billing_and_revenue_management_elastic_charging_engine = 11.3
  - communications_billing_and_revenue_management_elastic_charging_engine = 12.0
  - communications_calendar_server = 8.0.0.5.0
  - communications_calendar_server = 8.0.0.6.0
  - communications_cloud_native_core_automated_test_suite = 1.8.0
  - communications_cloud_native_core_binding_support_function = 1.9.0
  - communications_cloud_native_core_binding_support_function = 1.10.0
  - communications_cloud_native_core_console = 1.7.0
  - >-
    communications_cloud_native_core_network_function_cloud_native_environment =
    1.9.0
  - communications_cloud_native_core_network_repository_function = 1.14.0
  - communications_cloud_native_core_policy = 1.14.0
  - communications_cloud_native_core_security_edge_protection_proxy = 1.5.0
  - communications_cloud_native_core_security_edge_protection_proxy = 1.6.0
  - communications_cloud_native_core_security_edge_protection_proxy = 1.15.0
  - communications_cloud_native_core_service_communication_proxy = 1.14.0
  - communications_cloud_native_core_unified_data_repository = 1.14.0
  - communications_contacts_server = 8.0.0.3.0
patched:
  - hibernate_validator 6.0.18
published: '2019-11-08'
updated: '2026-08-21'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-10219'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2020:0159'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2020:0160'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2020:0161'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2020:0164'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2020:0445'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10219'
    label: secalert@redhat.com
  - url: >-
      https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56cee
    label: secalert@redhat.com
  - url: >-
      https://github.com/hibernate/hibernate-validator/commit/20d729548511ac5cff6fd459f93de137195420fe
    label: secalert@redhat.com
  - url: >-
      https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Adapted/CVE-2019-10219
    label: secalert@redhat.com
  - url: >-
      https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Origin/CVE-2019-10219/exploit
    label: secalert@redhat.com
  - url: >-
      https://lists.apache.org/thread.html/r4f8b4e2541be4234946e40d55859273a7eec0f4901e8080ce2406fe6%40%3Cnotifications.accumulo.apache.org%3E
    label: secalert@redhat.com
  - url: >-
      https://lists.apache.org/thread.html/r4f92d7f7682dcff92722fa947f9e6f8ba2227c5dc3e11ba09114897d%40%3Cnotifications.accumulo.apache.org%3E
    label: secalert@redhat.com
  - url: >-
      https://lists.apache.org/thread.html/r87b7e2d22982b4ca9f88f5f4f22a19b394d2662415b233582ed22ebf%40%3Cnotifications.accumulo.apache.org%3E
    label: secalert@redhat.com
  - url: >-
      https://lists.apache.org/thread.html/rb8dca19a4e52b60dab0ab21e2ff9968d78f4b84e4033824db1dd24b4%40%3Cpluto-scm.portals.apache.org%3E
    label: secalert@redhat.com
  - url: >-
      https://lists.apache.org/thread.html/rd418deda6f0ebe658c2015f43a14d03acb8b8c2c093c5bf6b880cd7c%40%3Cpluto-dev.portals.apache.org%3E
    label: secalert@redhat.com
  - url: >-
      https://lists.apache.org/thread.html/rf9c17c3efc4a376a96e9e2777eee6acf0bec28e2200e4b35da62de4a%40%3Cpluto-dev.portals.apache.org%3E
    label: secalert@redhat.com
  - url: 'https://security.netapp.com/advisory/ntap-20220210-0024/'
    label: secalert@redhat.com
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2020:0159'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0160'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0161'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0164'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0445'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10219'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56ceee
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/hibernate/hibernate-validator/commit/20d729548511ac5cff6fd459f93de137195420fe
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Adapted/CVE-2019-10219
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Origin/CVE-2019-10219/exploit
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r4f8b4e2541be4234946e40d55859273a7eec0f4901e8080ce2406fe6%40%3Cnotifications.accumulo.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r4f92d7f7682dcff92722fa947f9e6f8ba2227c5dc3e11ba09114897d%40%3Cnotifications.accumulo.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r87b7e2d22982b4ca9f88f5f4f22a19b394d2662415b233582ed22ebf%40%3Cnotifications.accumulo.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rb8dca19a4e52b60dab0ab21e2ff9968d78f4b84e4033824db1dd24b4%40%3Cpluto-scm.portals.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rd418deda6f0ebe658c2015f43a14d03acb8b8c2c093c5bf6b880cd7c%40%3Cpluto-dev.portals.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rf9c17c3efc4a376a96e9e2777eee6acf0bec28e2200e4b35da62de4a%40%3Cpluto-dev.portals.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20220210-0024/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.02167
epssPercentile: 0.81239
ingestedAt: '2026-08-21T15:18:35.127Z'
exploits:
  github: 2
  githubRepos:
    - >-
      https://github.com/shoucheng3/hibernate__hibernate-validator_CVE-2019-10219_6-0-17-Final
    - >-
      https://github.com/shoucheng3/hibernate__hibernate-validator_CVE-2019-10219_6_0_18_Final_fixed
  checkedAt: '2026-09-21T15:23:39.995Z'
exploitAvailable: true
---

## Overview

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

## Affected

- `hibernate_validator < 6.0.18`
- `hibernate_validator = 6.1.0`
- `fuse = 1.0`
- `jboss_data_grid`
- `jboss_enterprise_application_platform`
- `openshift_application_runtimes`
- `single_sign-on`
- `jboss_enterprise_application_platform = 7.2`
- `jboss_enterprise_application_platform = 7.3`
- `active_iq_unified_manager`
- `management_services_for_element_software_and_netapp_hci`
- `snapcenter_plug-in`
- `element`
- `access_manager = 11.1.2.3.0`
- `access_manager = 12.2.1.3.0`
- `access_manager = 12.2.1.4.0`
- `agile_engineering_data_management = 6.2.1.0`
- `agile_plm = 9.3.3`
- `agile_plm = 9.3.6`
- `agile_product_lifecycle_analytics = 3.6.1`
- `agile_product_lifecycle_management_integration_pack = 3.6`
- `airlines_data_model = 12.1.1.0.0`
- `airlines_data_model = 12.2.0.1.0`
- `application_express = 21.1.4`
- `application_performance_management = 13.4.1.0`
- `application_performance_management = 13.5.1.0`
- `application_testing_suite = 13.3.0.1`
- `argus_analytics = 8.2.1`
- `argus_analytics = 8.2.2`
- `argus_analytics = 8.2.3`
- `argus_analytics = 8.21`
- `argus_insight = 8.2.1`
- `argus_insight = 8.2.2`
- `argus_insight = 8.2.3`
- `argus_safety = 8.2.1`
- `argus_safety = 8.2.2`
- `argus_safety = 8.2.3`
- `banking_apis = 18.1`
- `banking_apis = 18.2`
- `banking_apis = 18.3`
- `banking_apis = 19.1`
- `banking_apis = 19.2`
- `banking_apis = 20.1`
- `banking_apis = 21.1`
- `banking_deposits_and_lines_of_credit_servicing = 2.12.0`
- `banking_digital_experience = 17.2`
- `banking_digital_experience = 18.1`
- `banking_digital_experience = 18.3`
- `banking_digital_experience = 19.1`
- `banking_digital_experience = 19.2`
- `banking_digital_experience = 20.1`
- `banking_digital_experience = 21.1`
- `banking_enterprise_default_management = 2.6.2`
- `banking_enterprise_default_management = 2.7.0`
- `banking_enterprise_default_management = 2.7.1`
- `banking_enterprise_default_management = 2.10.0`
- `banking_enterprise_default_management = 2.12.0`
- `banking_enterprise_default_managment >= 2.3.0, <= 2.4.0`
- `banking_loans_servicing = 2.12.0`
- `banking_party_management = 2.7.0`
- `banking_platform >= 2.3.0, <= 2.4.1`
- `banking_platform = 2.6.2`
- `banking_platform = 2.7.0`
- `banking_platform = 2.7.1`
- `bi_publisher = 5.5.0.0.0`
- `bi_publisher = 11.1.1.9.0`
- `bi_publisher = 12.2.1.3.0`
- `bi_publisher = 12.2.1.4.0`
- `big_data_spatial_and_graph = 23.1`
- `business_activity_monitoring = 12.2.1.4.0`
- `business_intelligence = 5.5.0.0.0`
- `business_intelligence = 5.9.0.0.0`
- `business_intelligence = 12.2.1.3.0`
- `business_intelligence = 12.2.1.4.0`
- `business_process_management_suite = 12.2.1.3.0`
- `business_process_management_suite = 12.2.1.4.0`
- `clinical = 5.2.1`
- `clinical = 5.2.2`
- `commerce_guided_search = 11.3.2`
- `commerce_platform >= 11.3.0, <= 11.3.2`
- `communications_application_session_controller = 3.9.0`
- `communications_billing_and_revenue_management = 12.0.0.3`
- `communications_billing_and_revenue_management = 12.0.0.4`
- `communications_billing_and_revenue_management_elastic_charging_engine = 11.3`
- `communications_billing_and_revenue_management_elastic_charging_engine = 12.0`
- `communications_calendar_server = 8.0.0.5.0`
- `communications_calendar_server = 8.0.0.6.0`
- `communications_cloud_native_core_automated_test_suite = 1.8.0`
- `communications_cloud_native_core_binding_support_function = 1.9.0`
- `communications_cloud_native_core_binding_support_function = 1.10.0`
- `communications_cloud_native_core_console = 1.7.0`
- `communications_cloud_native_core_network_function_cloud_native_environment = 1.9.0`
- `communications_cloud_native_core_network_repository_function = 1.14.0`
- `communications_cloud_native_core_policy = 1.14.0`
- `communications_cloud_native_core_security_edge_protection_proxy = 1.5.0`
- `communications_cloud_native_core_security_edge_protection_proxy = 1.6.0`
- `communications_cloud_native_core_security_edge_protection_proxy = 1.15.0`
- `communications_cloud_native_core_service_communication_proxy = 1.14.0`
- `communications_cloud_native_core_unified_data_repository = 1.14.0`
- `communications_contacts_server = 8.0.0.3.0`

## Remediation

Upgrade past the affected range:

- `hibernate_validator 6.0.18`
